Empowering Your Cybersecurity With the NIST Cybersecurity Framework (CSF)

NIST Cybersecurity Framework 2.0: What It Requires and How to Implement It

The NIST Cybersecurity Framework is the most widely referenced voluntary cybersecurity standard in the world — used by organizations across every sector to structure how they manage cybersecurity risk. In February 2024, NIST released CSF 2.0, the framework’s first major revision since its original 2014 publication, adding a sixth core function and extending the framework’s applicability well beyond its original critical infrastructure focus.

This guide covers what NIST CSF 2.0 actually requires across all six functions, what changed from the original framework, and how organizations implement it in practice — whether building a cybersecurity program from scratch or updating an existing CSF 1.1 implementation.

Executive Summary

Main Idea: NIST CSF 2.0 organizes cybersecurity risk management around six functions — Govern, Identify, Protect, Detect, Respond, and Recover — providing a structured, risk-based approach that applies to organizations of any size or sector. It is voluntary and not a regulation itself, but it underlies or maps directly to CMMC, FedRAMP, HIPAA Security Rule expectations, and most sector-specific compliance frameworks.

Why You Should Care: CSF 2.0’s most significant addition — the Govern function — reflects a shift in how regulators and auditors evaluate cybersecurity programs: not just whether technical controls exist, but whether cybersecurity risk management is genuinely integrated into organizational decision-making and overseen at the leadership level. Organizations still operating against CSF 1.1’s five-function structure are missing the governance expectation that CSF 2.0 made explicit — and that expectation increasingly shows up in vendor security questionnaires, cyber insurance underwriting, and board-level risk reporting.

Key Takeaways

  1. CSF 2.0 added a sixth function: Govern. The original 2014 framework organized cybersecurity risk management around five functions: Identify, Protect, Detect, Respond, and Recover. CSF 2.0, released in February 2024, added Govern as a foundational sixth function — establishing that cybersecurity risk management strategy, roles, policies, and oversight need to be explicitly defined and integrated into enterprise risk management, not just assumed to exist alongside the other five functions.
  2. CSF 2.0 explicitly extends beyond critical infrastructure to all organizations. The original CSF was developed primarily with critical infrastructure sectors in mind. CSF 2.0’s scope was deliberately broadened to serve any organization, regardless of sector, size, or existing cybersecurity maturity — reflecting how widely the framework has actually been adopted since 2014, well beyond its original target audience.
  3. NIST CSF is voluntary but functions as a de facto benchmark across compliance frameworks. itself is not a regulation and carries no direct penalty for noncompliance. But its structure and control expectations underlie or map closely to CMMC, FedRAMP’s Risk Management Framework, HIPAA Security Rule technical safeguards, and numerous state and sector-specific requirements. Organizations that build their cybersecurity program around CSF create a foundation that supports compliance across multiple regulatory frameworks simultaneously.
  4. Each function is organized into categories and subcategories with specific outcomes. CSF 2.0 is not a checklist of specific technical controls — it’s an outcomes-based framework. Each of the six functions breaks down into categories (specific outcome areas) and subcategories (more granular desired outcomes), which organizations then map to specific technical and organizational controls appropriate to their risk profile and existing frameworks like NIST SP 800-53.
  5. Implementation Tiers describe organizational maturity, not compliance levels. CSF 2.0 retains the four Implementation Tiers from the original framework — Partial, Risk Informed, Repeatable, and Adaptive — which describe how thoroughly cybersecurity risk management practices are integrated into organizational decision-making. Tiers are not a certification or maturity score for external validation; they’re a self-assessment tool for understanding and communicating an organization’s current state and improvement priorities.

What Changed From CSF 1.1 to CSF 2.0

NIST published the original Cybersecurity Framework in 2014 in response to a 2013 executive order directing the agency to develop a voluntary framework for reducing cyber risk to critical infrastructure. It quickly became a de facto standard well beyond that original scope, adopted by organizations of every size and sector, both in the United States and internationally.

CSF 2.0, published in February 2024, reflects a decade of real-world implementation experience and several deliberate changes:

The addition of the Govern function. This is the most substantive change. CSF 1.1 addressed governance concepts within the Identify function, but CSF 2.0 elevates governance to its own core function — establishing that an organization’s cybersecurity risk management strategy, expectations, and policy must be understood, established, communicated, and monitored, with clear executive and board-level oversight.

Explicit applicability to all organizations. CSF 2.0’s introductory language removes the original framework’s critical-infrastructure-specific framing, formally positioning the framework as applicable to any organization regardless of sector, size, or cybersecurity maturity.

Expanded implementation guidance. CSF 2.0 introduced Implementation Examples for many subcategories — concrete, illustrative actions organizations can take to achieve a given outcome — making the framework more actionable for organizations without deep in-house cybersecurity expertise.

Stronger supply chain risk management emphasis. CSF 2.0 significantly expands guidance on cybersecurity supply chain risk management, reflecting the growing recognition that third-party and vendor risk is a primary attack vector across most breaches.

The Six Functions of NIST CSF 2.0

Govern (GV). Establishes and monitors an organization’s cybersecurity risk management strategy, expectations, and policy. This function covers organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. In practice, Govern is where an organization defines who is accountable for cybersecurity risk decisions, how risk tolerance is set, and how the program is overseen at the leadership level.

Identify (ID). Develops an organizational understanding of cybersecurity risk to systems, assets, data, and capabilities. This includes asset management (knowing what hardware, software, and data exist and where), risk assessment, and improvement planning. An accurate, current inventory of systems and data flows is the foundation every other function depends on — an organization cannot protect, detect against, or recover assets it doesn’t know it has.

Protect (PR). Implements safeguards to ensure delivery of critical services and limit or contain the impact of a potential cybersecurity event. This covers identity management and access control, awareness and training, data security, platform security, and technology infrastructure resilience. Encryption, access controls, and data loss prevention capabilities primarily live in this function.

Detect (DE). Implements activities to identify the occurrence of a cybersecurity event in a timely manner. This covers continuous monitoring and adverse event analysis — the logging, monitoring, and anomaly detection capabilities that allow an organization to recognize when something has gone wrong before it becomes a full-scale incident.

Respond (RS). Implements activities to take action regarding a detected cybersecurity incident. This covers incident management, analysis, mitigation, and reporting and communication — including the internal and external communication (regulators, customers, partners) that many compliance frameworks separately mandate following a breach.

Recover (RC). Implements activities to restore assets and operations affected by a cybersecurity incident. This covers incident recovery planning and communication — the processes that get systems and data back to normal operations and that keep stakeholders informed throughout the recovery process.

How NIST CSF 2.0 Relates to Other Compliance Frameworks

CSF itself carries no direct penalty for noncompliance since it’s voluntary, but its function structure underlies or maps closely to frameworks that do carry compliance obligations.

CMMC and the NIST SP 800-171 controls it’s built on align closely with CSF’s Protect and Detect functions, particularly around access control, encryption, and audit logging. FedRAMP’s underlying Risk Management Framework (NIST SP 800-37) shares the same risk-based philosophy as CSF, and FedRAMP-authorized organizations have typically already implemented controls that map directly to CSF’s Identify and Protect functions. The HIPAA Security Rule’s administrative, physical, and technical safeguard categories correspond closely to CSF’s Govern, Protect, and Detect functions. Organizations building a cybersecurity program around CSF 2.0 create a foundation that supports compliance work across all of these frameworks simultaneously, rather than building separate, siloed programs for each regulatory requirement.

How Organizations Implement NIST CSF 2.0 in Practice

CSF 2.0 doesn’t prescribe specific technical controls — it defines desired outcomes that organizations achieve through controls appropriate to their environment, often drawn from more detailed standards like NIST SP 800-53.

Implementation typically starts with creating an organizational profile: selecting which CSF outcomes are relevant to the organization’s risk profile, mission, and existing regulatory obligations, and assessing current practices against those outcomes. This produces a current profile (where the organization stands today) and a target profile (where it needs to be), with the gap between them defining the improvement roadmap.

Implementation Tiers — Partial, Risk Informed, Repeatable, and Adaptive — describe how integrated and mature an organization’s risk management practices are, from ad hoc and reactive (Partial) to continuously improving and integrated into strategic decision-making (Adaptive). Tiers are self-assessed and used for internal planning and external communication, not as a certification or pass/fail measure.

How Kiteworks Supports NIST CSF 2.0 Implementation

Kiteworks provides capabilities that map to CSF 2.0’s functions across the sensitive data exchange channels an organization uses — secure email, secure file sharing, managed file transfer, SFTP, and secure data forms.

On Govern: granular user profile settings, role-based collaboration permissions, and external repository integration support the policy and oversight structures CSF 2.0’s Govern function requires.

On Identify: Kiteworks maintains accurate inventories of hardware, software, services, and the data flows moving through the platform, supporting the asset management foundation that CSF’s Identify function requires.

On Protect: identity management is enforced through granular role-based access controls, multi-factor authentication, and identity provider integration. AES-256 encryption at the file and disk level, with FIPS 140-3 validated cryptographic modules and customer-owned encryption keys, protects data at rest and in transit. SafeEDIT enables secure collaborative editing without the file leaving the governed environment.

On Detect: continuous monitoring, ongoing penetration testing, and proprietary anomaly detection patterns identify suspicious activity in real time, with SIEM integration and automated notifications supporting broader organizational detection capabilities.

On Respond and Recover: a single, consolidated, immutable audit trail across every Kiteworks channel provides the evidence needed for incident analysis and reporting, while clustering and virtual appliance architecture support the availability and resilience that recovery planning depends on.

To see how Kiteworks supports your organization’s NIST CSF 2.0 implementation, schedule a custom demo.

Frequently Asked Questions

NIST CSF 2.0, released in February 2024, is the first major revision to the NIST Cybersecurity Framework since its original 2014 publication. The most significant change is the addition of a sixth core function, Govern, which elevates cybersecurity governance, strategy, and oversight to a standalone function rather than treating it as a subset of the original Identify function. CSF 2.0 also explicitly broadens the framework’s applicability to organizations of any size or sector, rather than framing it primarily around critical infrastructure as the original version did, and adds more concrete implementation examples and expanded supply chain risk management guidance.

The six functions are Govern (establishing and monitoring cybersecurity risk management strategy and oversight), Identify (understanding organizational cybersecurity risk to systems, assets, and data), Protect (implementing safeguards like access controls and encryption), Detect (identifying cybersecurity events through monitoring and analysis), Respond (taking action on detected incidents, including reporting and communication), and Recover (restoring affected assets and operations). Each function is broken into categories and subcategories that define specific desired outcomes, which organizations achieve through controls appropriate to their environment.

NIST CSF is voluntary — it is not a law or regulation and carries no direct penalty for noncompliance. It applies to organizations of any sector or size that choose to adopt it, and CSF 2.0 explicitly broadened its stated scope beyond the framework’s original critical infrastructure focus to reflect how widely it has actually been used. While voluntary in itself, CSF’s structure underlies or closely maps to frameworks that do carry compliance obligations, including CMMC, FedRAMP’s Risk Management Framework, and HIPAA Security Rule expectations — making CSF adoption a practical foundation for organizations subject to those regulatory requirements.

Implementation Tiers describe how integrated and mature an organization’s cybersecurity risk management practices are, on a four-level scale: Partial (ad hoc, reactive practices), Risk Informed (risk management practices exist but aren’t formalized organization-wide), Repeatable (formal policies are established and consistently implemented), and Adaptive (risk management practices are continuously improving and fully integrated into organizational strategy). Tiers are a self-assessment and communication tool for understanding an organization’s current maturity and setting improvement priorities — they are not an external certification or a pass/fail compliance measure.

NIST CSF is a voluntary, outcomes-based framework, while CMMC and FedRAMP are compliance programs with mandatory requirements for specific populations of organizations. However, all three share underlying risk management philosophy and control expectations. CMMC’s requirements are built on NIST SP 800-171, which maps closely to CSF’s Protect and Detect functions. FedRAMP’s Risk Management Framework (NIST SP 800-37) shares the same core risk-based approach as CSF. Organizations that have implemented NIST CSF 2.0 across all six functions typically find they’ve already built much of the control foundation that CMMC and FedRAMP compliance requires, reducing the incremental work needed to achieve formal compliance with either program.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks